New Windows Zero-Day Exploit ‘RoguePlanet’ Released
A new Windows zero-day exploit, dubbed RoguePlanet, has been released by the threat actor Nightmare Eclipse, targeting Microsoft Defender and potentially leading to local privilege escalation and BitLocker bypass. This follows a series of similar zero-days released by the group, highlighting concerns about Microsoft’s vulnerability disclosure process and prompting a response from Microsoft including legal threats and account suspension.
The RoguePlanet exploit leverages a race condition in Microsoft Defender to achieve local privilege escalation, initially targeting remote code execution through tricking users into opening malicious .vhd(x) files on SMB servers. Furthermore, the exploit can bypass BitLocker encryption using a specialized device, redirecting cleaned files to NTFS.sys. Nightmare Eclipse has been actively targeting Microsoft products with multiple zero-days, including GreenPlasma, YellowKey, RedSun, UnDefend, and BlueHammer, often exploiting vulnerabilities before Microsoft’s Patch Tuesday updates. This activity has raised concerns about the group’s motives and Microsoft’s handling of vulnerability disclosures, leading to a tense exchange and subsequent actions by both parties.